BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- Date: Tue, 2 Dec 2014 19:42:43 +0000
- In-reply-to: <sjm8uiqc7sw.fsf@securerf.ihtfp.org>
- References: <546C4823.6060900@gmail.com> <BN3PR0401MB1204BAB10AE6249C54E4E81BDC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <54737E7C.5040506@mattgillen.net> <BN3PR0401MB1204CDD16766109B0CD095ECDC730@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uirdxem.fsf@securerf.ihtfp.org> <BN3PR0401MB1204B299B351DFF7F2E85FBDDC7D0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjmlhmqcb1j.fsf@securerf.ihtfp.org> <BN3PR0401MB120492A5BDE4D3CEE0AECDD3DC7A0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uiqc7sw.fsf@securerf.ihtfp.org>
> From: Derek Atkins [mailto:warlord at MIT.EDU] > > And you've already violated rule #1: You must trust your resolver. That's the point we've been talking about. I forget who said in this thread, that DNSSEC only provides security up to the last hop, not including the endpoint. It is unavoidable that people will travel; they will connect to the internet in coffee shops and hotels. It is not reasonable or realistic to expect them to trust their DNS resolver implicitly. You cannot trust the resolver, unless you are your own resolver, or the resolver relays security information to you which you're able to validate for yourself. It is unscalable for everybody to be their own resolver - breaking the distributed nature of DNS. So really, the only scalable solution is to provide security information to the endpoints. Unfortunately, it's also unrealistic to expect all the dumb linksys routers and comcast internet connections of the world to be upgraded in any timely manner to support relaying security information to endpoints. Yes it's possible for smart endpoints to query DNS providers as dictated by DHCP, and become their own secure resolvers if and only if the dumb DNS server failed to relay security information - but this starts out at the point of being currently unscalable. We'll probably get there someday, just obviously not right now.
- Follow-Ups:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] Python module for Windows services that runs on Linux
- Next by Date: [Discuss] Debian officially forked over systemd
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):